log4j-scan
canarytokens
log4j-scan | canarytokens | |
---|---|---|
20 | 27 | |
3,333 | 1,657 | |
0.0% | 1.2% | |
0.0 | 8.5 | |
over 1 year ago | 4 days ago | |
Python | Python | |
MIT License | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
log4j-scan
-
Sublime Music - A FLOSS desktop client for Subsonic API servers (Airsonic, Navidrome, Gonic, etc)
Testing the image with github.com/fullhunt/log4j-scan and https://github.com/quay/clair shows no vulnerabilities
-
Finding the "practical" component for my thesis on Log4Shell
https://github.com/cisagov/log4j-scanner https://github.com/fullhunt/log4j-scan https://github.com/portswigger/log4shell-scanner
- Here's a log4j-scan in case you want to find vulnerable hosts in the pool of servers you own
-
Log4j2 nightmares for self hosters?
https://github.com/fullhunt/log4j-scan Used this one for my network. Worked just fine and no setup required to run on my host.
-
How to Check if a Java Project Depends on A Vulnerable Version of Log4j
The team at FullHunt provided an open-source tool called log4j-scan, an automated and extensive scanner for finding vulnerable Log4j hosts. It allows teams to scan their infrastructure but also test for WAF (Web Application Firewall) bypasses that can result in code execution. The tool has several options but in short, you pass to the tool the URL to scan and you get a report on the vulnerabilities found. For example:
-
Log4j for Dummies: How to Determine if Your Server (or Docker Container) Is Affected by the Log4Shell Vulnerability
Yep. Seems like https://github.com/fullhunt/log4j-scan/issues/80 would fix my issue. Thanks for the assist.
- A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
- fullhunt/log4j-scan: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
- Log4j Vulnerability Cheatsheet
canarytokens
- 1Password detects "suspicious activity" in its internal Okta account
-
#Anonymous - AK - RABBIT MEET HOLE - #TheDEWFiles 3,000+ Docs On Tons Patents Various Tech, Studies, Research by TONs of Scientists on DEWs & Alternative Energy (Includes Aerospace Companies.)
Get a free OS in a VMand open any files in there. You should not trust a random batch of potentially backdoored or canarytoken'ed files
- What screams "I'm insecure"?
-
In your experience, what were some unconventional signs that there's a malware inside your network?
Throw some honeytokens/canarytokens on key systems. Thinkst has a free option where you can drop Word docs, PDF, AWS keys, etc. that will send you an email or webhook if they're ever used. https://canarytokens.org
-
IF you did door knocking, what would you leave behind?
QR code with some pdfs from inside a canarytokens.org folder.
- Increase in LockBit Ransomware
-
Worried someone has (or may gain) access to your UoG account? Try Canarytokens
You can generate Canarytokens for free on their website: https://www.canarytokens.org/generate. They're open-source, so if you're technically-inclined, you can run the software yourself: https://github.com/thinkst/canarytokens. All the documentation is here: https://docs.canarytokens.org/guide/.
- 1 minute Canaries
-
Please help me with internet stalker
I do not think a trap or "phishing link" is a good idea if she are getting serious threats! But it is not too hard, you can generate a few with here and if somebody opens the link you will get an email containing the time and IP address of who opened it: https://canarytokens.org (note that, you can not really do much with these information on your own).
-
Someone sending offensive material to people in our google domain
Good tip, OP could use this for quick setup. https://canarytokens.org
What are some alternatives?
log4jpwn - log4j rce test environment and poc
postman-app-support - Postman is an API platform for building and using APIs. Postman simplifies each step of the API lifecycle and streamlines collaboration so you can create better APIs—faster.
log4jscanner - A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.
tailscale - The easiest, most secure way to use WireGuard and 2FA.
mariadb-docker - Docker Official Image packaging for MariaDB
cli - Official Command Line Interface for the IPinfo API (IP geolocation and other types of IP data)
lunasec - LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
cli - GitHub’s official command line tool
log4jScanner - log4jScanner provides the ability to scan internal subnets for vulnerable log4j web services
anvil-runtime - The runtime engine for hosting Anvil web apps
syft - CLI tool and library for generating a Software Bill of Materials from container images and filesystems
hackclub - 🌎 Hack Club is a worldwide community of high school hackers. We make things. We help one another. We have fun.